---
title: [CM] [BDCB] [E3] [CRA] [P3] Risk Impact and Likelihood Assessment
description: [CM] [BDCB] [E3] [CRA] [P3] Risk Impact and Likelihood Assessment
image: https://blog.bcm-institute.org/hubfs/BDCB%20Graphic%20Folder/BDCB%20CM%20Graphic%20Folder/BDCB%20CM%20E3%20Morepost/%5BCM%5D%20%5BBDCB%5D%20%5BE3%5D%20%5BCRA%5D%20%5BP3%5D%20Risk%20Impact%20and%20Likelihood%20Assessment.jpg
---

.

[![BCMIWhiteLogo.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogo.png?width=556&name=BCMIWhiteLogo.png "BCMIWhiteLogo.png")](http://www.bcm-institute.org/)

- [Home](https://www.bcm-institute.org/)
- [About Us](https://www.bcm-institute.org/about-us-3/) 
    - [A President’s Perspective](https://www.bcm-institute.org/about-us/a-presidents-perspective/)
    - [Our History](https://www.bcm-institute.org/about-us/our-history/)
    - [Our Advisory Council](https://www.bcm-institute.org/about-us/our-advisory-council/)
    - [Customers’ Testimonials](https://www.bcm-institute.org/about-us/customers-testimonials/)
    - [Credential Verification](https://www.bcm-institute.org/about-us/credential-verification/)
- [Courses](https://blog.bcm-institute.org/blog/course-fees-for-blended-learning-courses-master-catalog) 
    - [ISO 22301 Business Continuity Management System Audit](https://blog.bcm-institute.org/audit/business-continuity-management-audit-courses)
    - [ISO 22301 Business Continuity Management](https://blog.bcm-institute.org/bcm/business-continuity-management-courses)
    - [Crisis Communication](https://blog.bcm-institute.org/crisis-communication/crisis-communication-courses)
    - [Crisis Management](https://blog.bcm-institute.org/en/crisis-management/courses)
    - [IT Disaster Recovery](https://blog.bcm-institute.org/it-disaster-recovery/courses)
    - [Operational Resilience](https://blog.bcm-institute.org/operational-resilience/courses)
    - [Operational Resilience Audit](https://blog.bcm-institute.org/operational-resilience-audit/courses)
- [Certification](https://blog.bcm-institute.org/certification/types-of-certifications-offered) 
    - [ISO 22301 BCMS Audit Certification](https://blog.bcm-institute.org/certification/business-continuity-management-audit-certification)
    - [ISO22301 Business Continuity Management Certification](https://blog.bcm-institute.org/bcm/business-continuity-management-certification)
    - [Crisis Communication Certification](https://blog.bcm-institute.org/crisis-communication/crisis-communication-certification)
    - [Crisis Management Certification](https://blog.bcm-institute.org/en/crisis-management/crisis-management-certification)
    - [IT Disaster Recovery Planning Certification](https://blog.bcm-institute.org/it-disaster-recovery/it-disaster-recovery-certification)
    - [Operational Resilience Certification](https://blog.bcm-institute.org/operational-resilience/operational-resilience-certification)
    - [Operational Resilience Audit Certification](https://blog.bcm-institute.org/operational-resilience-audit)
- [Seminars](https://blog.bcm-institute.org/meet-the-expert/mte-webinar-mainpage)
- [Store](https://www.bcm-institute.org/store-2/)
- [Contact Us](http://www.bcm-institute.org/about-us/contact-us/)

- <https://www.facebook.com/BCMInstitute/>
- <https://www.linkedin.com/company/business-continuity-management-institute-bcm-institute>

##### Crisis Management in Action: A Practical Implementation Guide for BDCB

![CM 7P\_CMS1\_with Cert Logo](https://blog.bcm-institute.org/hs-fs/hubfs/BB%20CM%20%5BAi%20Gen%20Blog%20Photo%5D/BB%20CM%20PM%20P1-7/CM%207P_CMS1_with%20Cert%20Logo.jpg?width=2000&height=1333&name=CM%207P_CMS1_with%20Cert%20Logo.jpg "CM 7P_CMS1_with Cert Logo")

# \[CM\] \[BDCB\] \[E3\] \[CRA\] \[P3\] Risk Impact and Likelihood Assessment

[![\[CM\] \[BDCB\] \[Full Banner\] Crisis Management in Action\_ A Practical Implementation Guide for BDCB](https://no-cache.hubspot.com/cta/default/3893111/399bc296-6bd2-4c03-8819-8bfe517a3e07.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/399bc296-6bd2-4c03-8819-8bfe517a3e07)

**CRA Part 3 — Risk Impact and Likelihood Assessment** continues the Crisis Risk Assessment developed in **CRA Part 1-1 — List of Threats** and **CRA Part 2 — Treatment and Control** for Brunei Darussalam Central Bank (BDCB).

BCMpedia's RAR methodology assesses each identified threat against seven impact areas: **Finance; Operations; Legal & Regulatory; Reputation & Image; Social Responsibility; People; and Assets/IT Systems/Information**.

Each area is scored from **1 (Very Low/Insignificant) to 5 (Very High/Catastrophic)**.

The highest of the seven scores becomes the **Risk Impact Area — Highest Numeric Score**.

Likelihood is also assessed on a five-point scale: **1 Very Low, 2 Low, 3 Medium, 4 High, and 5 Very High**.

Risk Rating is then calculated as **Highest Impact × Likelihood**. BCMpedia maps the resulting rating to risk levels of Very Low, Low, Medium, High, and Very High.

The **Expected Period of Disruption** represents the estimated residual period for which operations could be disrupted or access denied after considering existing controls.

[![\[Banner\] \[Title\] \[CM\] \[E3\] Part 3\_ Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/d550d6b9-dc02-4d39-814a-705d2362bd77.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d550d6b9-dc02-4d39-814a-705d2362bd77)

[Moh Heng Goh](https://blog.bcm-institute.org/en/ebook-cm/author/moh-heng-goh) Oct 7, 2026

###### Crisis Management Certified Planner-Specialist-Expert

##### [![\[CM\] \[BDCB\] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/062c8304-1699-4f7b-a38d-f128d9815304.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/062c8304-1699-4f7b-a38d-f128d9815304)[![\[Banner\] \[Title\] \[CM\] \[E3\] Part 3\_ Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/d550d6b9-dc02-4d39-814a-705d2362bd77.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d550d6b9-dc02-4d39-814a-705d2362bd77)

### **[![\[CM\] \[Table\] \[CRA 3-1\] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/69d85f1f-70e9-4fe2-8564-b7b36ebadb54.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/69d85f1f-70e9-4fe2-8564-b7b36ebadb54)**

### **Part 3: Risk Impact and Likelihood Assessment for Brunei Darussalam Central Bank**

#### **Introduction**

**[![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P3\] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/7a44ac98-15cf-427b-b8fa-011061502369.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/7a44ac98-15cf-427b-b8fa-011061502369)CRA Part 3 — Risk Impact and Likelihood Assessment** continues the Crisis Risk Assessment developed in **CRA Part 1-1 — List of Threats** and **CRA Part 2 — Treatment and Control** for Brunei Darussalam Central Bank (BDCB).

BCMpedia's RAR methodology assesses each identified threat against seven impact areas: **Finance; Operations; Legal & Regulatory; Reputation & Image; Social Responsibility; People; and Assets/IT Systems/Information**.

Each area is scored from **1 (Very Low/Insignificant) to 5 (Very High/Catastrophic)**.

The highest of the seven scores becomes the **Risk Impact Area — Highest Numeric Score**.

Likelihood is also assessed on a five-point scale: **1 (Very Low), 2 (Low), 3 (Medium), 4 (High), and 5 (Very High)**.

Risk Rating is then calculated as **Highest Impact × Likelihood**. BCMpedia maps the resulting rating to risk levels of Very Low, Low, Medium, High, and Very High.

The **Expected Period of Disruption** represents the estimated residual period for which operations could be disrupted or access denied after considering existing controls.

For BDCB, impact assessment must recognise its wider systemic role.

BDCB's core functions include currency issuance and management, monetary policy, and supervision of banks and financial institutions, while its objectives include financial-system stability and efficient payment systems.

BDCB also operates Brunei Darussalam's RTGS, ACH, and CSD systems; RTGS supports large-value and urgent interbank payments, ACH supports bulk clearing, and CSD supports government securities and related settlement activities.

**Important:** The scores below are **illustrative CRA working assessments**, not BDCB-approved risk ratings.

BDCB risk owners should validate them using actual incident history, controls, locations, technology architecture, supplier arrangements, and approved risk criteria.

#### **Scoring Legend**

 

| Score | Impact | Likelihood |
| --- | --- | --- |
| 1 | Very Low | Very Low / Rare |
| 2 | Low | Low |
| 3 | Medium | Medium |
| 4 | High | High |
| 5 | Very High | Very High / Almost Certain |

For consistency in this working assessment, Risk Level is interpreted as **1–5 Very Low; 6–10 Low; 11–15 Medium; 16–20 High; 21–25 Very High**.

BCMpedia itself displays an overlap at rating 20 in its published bands, so BDCB should ultimately apply its approved internal risk matrix.

#### **CRA Part 3 — Risk Impact and Likelihood Assessment**

 

| Crisis Type | Type of Crisis Scenario | Finance | Operations | Legal & Regulatory | Reputation & Image | Social Responsibility | People | Assets / IT / Information | Highest Score | Likelihood | Risk Rating | Risk Level | Expected Period of Disruption |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Denial of Access – Natural Disaster | Flood | 3 | 4 | 3 | 3 | 3 | 4 | 4 | 4 | 3 | 12 | Medium | 1–3 days |
| Flash Flood | 3 | 4 | 2 | 3 | 3 | 4 | 4 | 4 | 3 | 12 | Medium | 4–24 hours |  |
| Severe Rain / Thunderstorm | 2 | 3 | 2 | 2 | 2 | 3 | 3 | 3 | 4 | 12 | Medium | 2–12 hours |  |
| Lightning | 2 | 3 | 2 | 2 | 2 | 2 | 4 | 4 | 3 | 12 | Medium | 2–24 hours |  |
| Strong Wind / Windstorm | 2 | 3 | 2 | 2 | 2 | 3 | 3 | 3 | 3 | 9 | Low | 4–24 hours |  |
| Tropical Storm | 3 | 4 | 3 | 3 | 4 | 4 | 4 | 4 | 2 | 8 | Low | 1–3 days |  |
| Haze / Poor Air Quality | 2 | 3 | 2 | 2 | 3 | 4 | 2 | 4 | 3 | 12 | Medium | 1–5 days |  |
| Earthquake Tremors | 3 | 4 | 2 | 3 | 3 | 5 | 4 | 5 | 1 | 5 | Very Low | 1–3 days |  |
| External Fire / Wildfire | 3 | 4 | 2 | 3 | 3 | 4 | 4 | 4 | 2 | 8 | Low | 1–3 days |  |
| Denial of Access – Man-made Disaster | Building Fire | 4 | 5 | 4 | 4 | 3 | 5 | 5 | 5 | 2 | 10 | Low | 3–14 days |
| Bomb Threat | 2 | 4 | 3 | 4 | 3 | 4 | 3 | 4 | 2 | 8 | Low | 4–24 hours |  |
| Explosion | 4 | 5 | 4 | 5 | 4 | 5 | 5 | 5 | 1 | 5 | Very Low | 3–30 days |  |
| Terrorism / Hostile Attack | 4 | 5 | 4 | 5 | 5 | 5 | 5 | 5 | 1 | 5 | Very Low | 3–30 days |  |
| Civil Disturbance / Public Disorder | 2 | 3 | 2 | 4 | 4 | 3 | 2 | 4 | 2 | 8 | Low | 4–48 hours |  |
| Suspicious Package / Security Threat | 2 | 3 | 2 | 3 | 2 | 4 | 2 | 4 | 2 | 8 | Low | 2–12 hours |  |
| Hazardous Material Incident | 3 | 4 | 4 | 4 | 4 | 5 | 4 | 5 | 1 | 5 | Very Low | 1–7 days |  |
| Major Transport Accident Near Premises | 2 | 3 | 2 | 2 | 3 | 4 | 3 | 4 | 2 | 8 | Low | 4–24 hours |  |
| Prolonged Power Outage | 3 | 5 | 3 | 4 | 4 | 3 | 5 | 5 | 3 | 15 | Medium | 4–48 hours |  |
| Unavailability of People | Infectious Disease / Pandemic | 4 | 5 | 4 | 4 | 5 | 5 | 2 | 5 | 3 | 15 | Medium | 1–8 weeks |
| Localised Infectious Disease Outbreak | 2 | 4 | 3 | 3 | 3 | 5 | 2 | 5 | 3 | 15 | Medium | 3–14 days |  |
| Loss of Key Appointment Holder | 2 | 4 | 3 | 3 | 2 | 4 | 2 | 4 | 2 | 8 | Low | 1–10 days |  |
| Multiple Critical Staff Unavailable | 3 | 5 | 4 | 4 | 3 | 5 | 2 | 5 | 3 | 15 | Medium | 3–14 days |  |
| Workplace Accident / Safety Incident | 2 | 3 | 4 | 3 | 3 | 5 | 3 | 5 | 2 | 10 | Low | 4 hours–3 days |  |
| Workplace Violence | 2 | 4 | 4 | 5 | 3 | 5 | 3 | 5 | 2 | 10 | Low | 1–5 days |  |
| Labour Dispute Affecting Essential Services | 3 | 4 | 3 | 3 | 4 | 3 | 3 | 4 | 2 | 8 | Low | 1–7 days |  |
| Transport Disruption Affecting Workforce | 2 | 4 | 2 | 2 | 3 | 4 | 2 | 4 | 3 | 12 | Medium | 4–24 hours |  |
| Mass Casualty / National Emergency | 4 | 5 | 4 | 5 | 5 | 5 | 4 | 5 | 1 | 5 | Very Low | 3 days–4 weeks |  |
| Disruption to the Supply Chain | Loss of Specialised Technology Vendor | 3 | 4 | 3 | 3 | 3 | 2 | 4 | 4 | 2 | 8 | Low | 1–5 days |
| Telecommunications Provider Failure | 3 | 5 | 3 | 4 | 4 | 3 | 5 | 5 | 3 | 15 | Medium | 2–24 hours |  |
| Utility Supplier Failure | 3 | 4 | 2 | 3 | 3 | 3 | 4 | 4 | 3 | 12 | Medium | 4–48 hours |  |
| Critical ICT / Cloud Service Provider Outage | 4 | 5 | 4 | 4 | 4 | 2 | 5 | 5 | 3 | 15 | Medium | 2–24 hours |  |
| Cyberattack on Critical Supplier | 4 | 5 | 4 | 5 | 4 | 3 | 5 | 5 | 3 | 15 | Medium | 1–5 days |  |
| Security Service Provider Failure | 2 | 3 | 3 | 3 | 2 | 4 | 3 | 4 | 2 | 8 | Low | 4–24 hours |  |
| Critical Equipment Supplier Failure | 3 | 4 | 2 | 3 | 3 | 2 | 4 | 4 | 2 | 8 | Low | 1–7 days |  |
| Logistics / Transportation Disruption | 3 | 4 | 2 | 3 | 4 | 3 | 3 | 4 | 3 | 12 | Medium | 1–5 days |  |
| Supplier Financial Failure | 3 | 4 | 3 | 3 | 2 | 2 | 3 | 4 | 2 | 8 | Low | 3–14 days |  |
| Regulatory / Legal Failure Affecting Supplier | 3 | 4 | 4 | 4 | 3 | 2 | 3 | 4 | 2 | 8 | Low | 3–14 days |  |
| Concentration / Common Supplier Failure | 4 | 5 | 4 | 5 | 5 | 3 | 5 | 5 | 3 | 15 | Medium | 1–5 days |  |
| Equipment and IT-Related Disruption | Hardware Failure | 2 | 4 | 2 | 3 | 3 | 2 | 5 | 5 | 3 | 15 | Medium | 2–12 hours |
| Software / Application Failure | 3 | 4 | 3 | 3 | 3 | 2 | 5 | 5 | 3 | 15 | Medium | 2–12 hours |  |
| Network Failure | 3 | 5 | 3 | 4 | 4 | 2 | 5 | 5 | 3 | 15 | Medium | 1–12 hours |  |
| Telecommunications Failure | 3 | 5 | 3 | 4 | 4 | 3 | 5 | 5 | 3 | 15 | Medium | 2–24 hours |  |
| Cyberattack | 5 | 5 | 5 | 5 | 5 | 4 | 5 | 5 | 4 | 20 | High | 1–7 days |  |
| Ransomware | 5 | 5 | 5 | 5 | 4 | 3 | 5 | 5 | 3 | 15 | Medium | 2–14 days |  |
| Distributed Denial-of-Service (DDoS) | 3 | 4 | 3 | 4 | 4 | 2 | 5 | 5 | 3 | 15 | Medium | 1–12 hours |  |
| IT Sabotage | 4 | 5 | 5 | 5 | 4 | 3 | 5 | 5 | 2 | 10 | Low | 1–7 days |  |
| Data Corruption / Loss of Data Integrity | 5 | 5 | 5 | 5 | 4 | 2 | 5 | 5 | 3 | 15 | Medium | 1–5 days |  |
| Data Breach / Information Leakage | 4 | 4 | 5 | 5 | 4 | 4 | 5 | 5 | 3 | 15 | Medium | 1–7 days\* |  |
| RTGS System Disruption | 5 | 5 | 5 | 5 | 5 | 2 | 5 | 5 | 3 | 15 | Medium | 1–8 hours |  |
| ACH System Disruption | 4 | 5 | 4 | 4 | 4 | 2 | 5 | 5 | 3 | 15 | Medium | 2–12 hours |  |
| CSD System Disruption | 4 | 5 | 4 | 4 | 3 | 2 | 5 | 5 | 2 | 10 | Low | 2–12 hours |  |
| Data Centre Failure | 5 | 5 | 4 | 5 | 4 | 3 | 5 | 5 | 2 | 10 | Low | 4–48 hours |  |
| Disaster Recovery / Failover Failure | 5 | 5 | 4 | 5 | 5 | 2 | 5 | 5 | 2 | 10 | Low | 1–5 days |  |
| Failed Technology Change / Upgrade | 4 | 5 | 4 | 4 | 4 | 2 | 5 | 5 | 3 | 15 | Medium | 2–24 hours |  |
| Database Failure | 4 | 5 | 4 | 4 | 4 | 2 | 5 | 5 | 3 | 15 | Medium | 2–24 hours |  |
| Authentication / Identity Service Failure | 3 | 5 | 3 | 4 | 3 | 2 | 5 | 5 | 3 | 15 | Medium | 1–12 hours |  |
| UPS / Backup Generator Failure | 3 | 4 | 2 | 3 | 3 | 3 | 5 | 5 | 2 | 10 | Low | 2–24 hours |  |
| HVAC / Cooling Failure | 3 | 4 | 2 | 3 | 3 | 3 | 5 | 5 | 2 | 10 | Low | 2–24 hours |  |
| Capacity / Performance Failure | 4 | 5 | 4 | 4 | 5 | 2 | 5 | 5 | 3 | 15 | Medium | 1–8 hours |  |

\*For a data breach, the table records the estimated **operational disruption period** rather than the potentially much longer investigation, legal, regulatory, and reputational remediation period.

#### **Interpretation of the Seven Impact Areas**

Consider the seven impact dimensions separately rather than assigning a single intuitive severity score at the outset.

BCMpedia defines them around financial loss; disruption to critical operations; legal, regulatory, and contractual consequences; reputation; public/community interests; personnel; and critical assets, technology, telecommunications, and information.

For BDCB, **Operations** should consider disruption to central-bank activities rather than only ordinary administrative processes

This includes currency-related activities, monetary operations, financial-sector supervision, payment-system responsibilities, and other critical services.

BDCB's statutory role means interrupting some activities can have consequences beyond the organisation itself.

**Social Responsibility** is particularly important in the BDCB context because an event can affect financial institutions, businesses, and the public. BDCB states that its objectives include financial system stability and efficient payment systems.

**Assets/IT Systems/Information** includes physical facilities and equipment as well as ICT systems, telecommunications, and information.

This dimension is therefore especially significant for cyberattacks, data corruption, data-centre failure, and payment-system disruptions.

#### **BDCB-Specific Critical Risk Considerations**

Several scenarios deserve particular management attention, even where their calculated Risk Rating is not the highest in the table.

##### **Cyberattack**

Cyberattack has been assigned a working rating of **20 (High)** because the consequences could extend across virtually every impact dimension.

A serious attack could simultaneously compromise systems, information, operations, and stakeholder confidence.

The likelihood score of 4 is an **illustrative planning assumption**, not a claim about the current probability of a successful attack against BDCB.

Replace it with a likelihood derived from BDCB's threat intelligence, incident history, and control effectiveness.

##### **RTGS Disruption**

RTGS deserves special consideration even though its illustrative rating is 15. BDCB describes RTGS as the heart of a modern national payment system.

It processes large-value and urgent interbank payments, settled using funds held in Brunei Dollar settlement accounts at BDCB.

BDCB also characterises RTGS as systemically important and states that such a system needs to be reliable, robust, and resilient even during market crises.

Consequently, a relatively short RTGS outage may warrant a higher management escalation priority than a longer disruption to a less critical internal activity.

##### **ACH Disruption**

ACH facilitates bulk clearing of debit and credit instruments, including direct credit transfers such as payroll. Its payment obligations are ultimately submitted to RTGS for settlement.

This creates an important interdependency:

###### **ACH availability is not sufficient if downstream RTGS settlement capability is unavailable.**

Scenario assessment should therefore consider combined failures rather than assessing each platform independently.

##### **CSD Disruption**

CSD maintains electronic records for Government debt securities and supports auctions, securities transfers, secondary-market activity, and collateral-management functionality.

Its disruption could consequently have financial-market and monetary-operation implications that extend beyond a conventional application outage.

##### **Data Integrity**

Data corruption has a maximum impact score because system availability alone does not ensure operational safety.

A system may technically be operating while producing inaccurate or corrupted information.

For BDCB, the key question is therefore not simply:

###### **“Is the system available?”**

but also:

###### **“Can the information and transactions produced by the system be trusted?”**

#### **Understanding Likelihood**

Likelihood should represent the probability of the threat occurring within BDCB's actual operating environment.

BCMpedia recommends a 1–5 scale and notes that organisations should obtain the appropriate likelihood descriptions from their own risk-management framework where available.

This is important because the scores in this chapter should **not** be interpreted as statistical predictions.

For example, an earthquake and a cyberattack may both have potentially catastrophic consequences. Their likelihoods, however, can differ substantially. Consequently:

**Earthquake:** Impact 5 × Likelihood 1 = **5**

**Cyberattack:** Impact 5 × Likelihood 4 = **20**

The resulting rating allows the organisation to distinguish between **severity** and **probability**.

A low calculated risk rating should therefore never be interpreted as meaning that the consequence is unimportant.

A rare but catastrophic event may still require crisis planning because the organisation cannot tolerate being completely unprepared.

#### **Understanding the Expected Period of Disruption**

The Expected Period of Disruption is not the total time required to resolve every consequence of a crisis.

BCMpedia defines it as the expected residual period during which operations are disrupted or primary-location access is denied after existing controls are considered.

This distinction matters for BDCB.

A cyberattack might interrupt critical systems for three days but require months of investigation and remediation.

A data breach might create only limited operational downtime but generate extended legal, regulatory, and reputational consequences.

A building fire might deny access to the primary facility for weeks, while effective alternate-site arrangements enable critical functions to resume much earlier.

A payment-system incident could last only several hours yet have very high operational significance because of the time-sensitive nature of settlement.

Consequently, the expected disruption period should ultimately be aligned with BDCB's **business impact analysis, recovery objectives, crisis escalation criteria, and technology recovery requirements**.

#### **Relationship Between CRA Part 1, Part 2, and Part 3**

The three CRA components should form a continuous assessment process.

**CRA Part 1-1 — Threat Identification** establishes **what could happen**.

**CRA Part 2 — Treatment and Control** establishes **what BDCB currently does, or plans to do, about the threat**.

**CRA Part 3 — Risk Analysis** establishes **how serious the remaining exposure is and which risks require management priority**.

The result should enable BDCB to determine whether existing controls reduce each risk sufficiently or whether additional treatment is necessary.

#### **Using the Assessment for Crisis Management**

The CRA should not end with assigning a numeric Risk Rating. The results should feed directly into BDCB's crisis-management programme.

Scenarios with significant impact, important systemic consequences, or substantial residual exposure should be considered for:

- crisis-management plans and playbooks;
- crisis escalation criteria;
- early-warning indicators;
- Crisis Management Team activation thresholds;
- business continuity strategies;
- cyber incident response;
- IT disaster recovery;
- supplier contingency arrangements;
- stakeholder communication plans; and
- severe-but-plausible crisis exercises.

The highest numerical risk is also **not automatically the only scenario that deserves crisis exercise coverage**.

Low-likelihood/high-impact scenarios remain important where failure would threaten life safety, critical central-bank responsibilities, or financial-system stability.

#### **Management Validation**

Before the table becomes BDCB's approved CRA Part 3, the relevant risk owner should validate each assessment.

Particular attention should be given to the assumptions behind:

**Impact scores** — What evidence supports the assigned consequences?

**Likelihood** — What historical, threat-intelligence, or control information supports the probability assessment?

**Existing controls** — Are the controls documented, implemented, and tested?

**Expected disruption** — Is the estimate supported by recovery testing and operational experience?

**Interdependencies** — Could another failure prevent the assumed recovery arrangement from working?

**Residual risk** — Is the resulting exposure within BDCB's approved risk appetite?

This validation is essential because the numeric scores in this implementation guide are intended to illustrate the methodology rather than substitute for BDCB's formal risk assessment.

 

[![Banner \[CM\] \[Summing Up\] \[E3\] \[CRA\] \[P3\] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/a3d3e509-b109-4c48-8c77-a5ea9d82df3a.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/a3d3e509-b109-4c48-8c77-a5ea9d82df3a)

CRA Part 3 provides BDCB with a structured method for translating its threat catalogue into an assessment of **impact, likelihood, risk rating, risk level and expected disruption**.

The methodology is particularly useful for BDCB because it cannot assess risk exposure solely from the perspective of internal operational loss.

Its responsibilities include currency issuance and management, monetary policy, supervision of financial institutions, financial-system stability and efficient payment systems.

The operation of RTGS, ACH and CSD creates an additional dimension. Disruption to these platforms can affect financial institutions and financial-market activities rather than BDCB alone.

The assessment should therefore consider three questions for every threat:

- **How severely could this affect BDCB?**
- **How likely is it to occur after considering the operating environment and controls?**
- **Could its consequences extend from BDCB into Brunei Darussalam's wider financial system?**

The resulting CRA Part 3 becomes an important decision-support tool for prioritising risk treatment, strengthening controls, establishing crisis escalation thresholds and selecting scenarios for exercises.

Used together with **CRA Part 1-1** and **CRA Part 2**, it provides BDCB with a structured progression from **threat identification → treatment and control → residual risk assessment → crisis preparedness and continuous improvement**.

 

 

**[![\[CM\] \[BDCB\] \[3/4 Banner\] Crisis Management in Action\_ A Practical Implementation Guide for BDCB](https://no-cache.hubspot.com/cta/default/3893111/b3d8c34f-d579-45e8-aba7-c04de5f90bb2.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b3d8c34f-d579-45e8-aba7-c04de5f90bb2)**

| **eBook 3: Starting Your CM Implementation** |  |  |  |
| --- | --- | --- | --- |
| \[RAR\] \[P1-1\] | \[RAR\] \[P1-2\] | \[RAR\] \[P1-3\] | \[RAR\] \[P2\] |
| [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6) | [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-2\] List of Crisis Scenarios \[Natural and Man-made\]](https://no-cache.hubspot.com/cta/default/3893111/029d6134-feb9-446e-884c-562eb4fd8e70.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/029d6134-feb9-446e-884c-562eb4fd8e70) | [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P1-3\] List of Crisis Scenarios \[Technology\] ](https://no-cache.hubspot.com/cta/default/3893111/883a9c65-15e5-408d-a406-3835732e8f16.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/883a9c65-15e5-408d-a406-3835732e8f16) | [![\[CM\] \[BDCB\] \[E3\] \[RAR\] \[P2\] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/a122225c-4e8c-435a-8268-4e24d1d834bf.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/a122225c-4e8c-435a-8268-4e24d1d834bf) |
| \[RAR\] \[P3\] | \[CMS\] \[P1\] | \[CMS\] \[P2\] | eBook 3 |
| [![\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P3\] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/7a44ac98-15cf-427b-b8fa-011061502369.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/7a44ac98-15cf-427b-b8fa-011061502369) | [![\[CM\] \[BDCB\] \[E3\] \[CMS\] \[P1\] Crisis Prevention Strategy](https://no-cache.hubspot.com/cta/default/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d) | [![\[CM\] \[BDCB\] \[E3\] \[CMS\] \[P2\] Crisis Response Strategy](https://no-cache.hubspot.com/cta/default/3893111/0dacc52b-d723-44a2-999f-66752a10d897.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/0dacc52b-d723-44a2-999f-66752a10d897) | [![eBook Cover \[CM\] \[BDCB\] \[E3\] \[2D\]](https://no-cache.hubspot.com/cta/default/3893111/77f3104a-2f3b-4e2b-a101-9e72c37001c2.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/77f3104a-2f3b-4e2b-a101-9e72c37001c2) |
|  |  |  |  |

 

#### More Information About Crisis Management Blended/ Hybrid Learning Courses

To learn more about the course and schedule, click the buttons below for the  CM-300 Crisis Management Implementer \[CM-3\] and the CM-5000 Crisis Management Expert Implementer \[CM-5\].

| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/5ffecd2d-8000-4805-b5e3-e9ead2e259cc.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/5ffecd2d-8000-4805-b5e3-e9ead2e259cc) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/c3546220-6c76-4a10-8c76-4040b94e09e5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c3546220-6c76-4a10-8c76-4040b94e09e5) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/03294547-1df3-435c-9243-971c3d9bb6ce.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/03294547-1df3-435c-9243-971c3d9bb6ce) |
| --- | --- | --- |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/b29594fe-d44a-4ff8-8160-03f7ce454385.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b29594fe-d44a-4ff8-8160-03f7ce454385) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/dd120e7f-9fe2-49ed-ad24-489b81c06739.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/dd120e7f-9fe2-49ed-ad24-489b81c06739) | [![\[BL-CM\] \[5\] Register](https://no-cache.hubspot.com/cta/default/3893111/82024308-16f4-4491-98be-818a882c6286.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/82024308-16f4-4491-98be-818a882c6286) |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/c8aaf76b-4c0b-402a-ad12-c8aff24eb911.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c8aaf76b-4c0b-402a-ad12-c8aff24eb911) | Please feel free to send us a note if you have any questions. [![Email to Sales Team \[BCM Institute\]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e) | [![FAQ BL-CM-5 CM-5000](https://no-cache.hubspot.com/cta/default/3893111/30bcbbbf-c8ea-48d8-8643-da2638f3f0f8.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/30bcbbbf-c8ea-48d8-8643-da2638f3f0f8) |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/83d00c12-c51c-4476-9902-69f9b7667a91.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/83d00c12-c51c-4476-9902-69f9b7667a91) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/672d2949-6233-4b26-ad42-ae0dd0a1a3ac.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/672d2949-6233-4b26-ad42-ae0dd0a1a3ac) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/3ca6f50d-a3c5-41b8-8da2-26feb8a7613e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3ca6f50d-a3c5-41b8-8da2-26feb8a7613e) |

### Your Comments Here:

 

![CTA Banner\_OR](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_OR.jpg "CTA Banner_OR")

---

![CTA Banner\_ORA](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_ORA.jpg "CTA Banner_ORA")

---

![CTA Banner\_BCM](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_BCM.jpg "CTA Banner_BCM")

---

![CTA Banner\_ITDR](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_ITDR.jpg "CTA Banner_ITDR")

---

![CTA Banner\_CM](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_CM.jpg "CTA Banner_CM")

![BCMIWhiteLogoSmall.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogoSmall.png?width=72&name=BCMIWhiteLogoSmall.png "BCMIWhiteLogoSmall.png")

All rights reserved. Copyright 2026

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Moh Heng Goh",
    "url" : "https://blog.bcm-institute.org/en/ebook-cm/author/moh-heng-goh"
  },
  "dateModified" : "2026-10-09T08:21:30.804Z",
  "datePublished" : "2026-10-07T08:21:16.000Z",
  "headline" : "[CM] [BDCB] [E3] [CRA] [P3] Risk Impact and Likelihood Assessment",
  "mainEntityOfPage" : {
    "@id" : "https://blog.bcm-institute.org/en/ebook-cm/cm-bdcb-e3-cra-p3-risk-impact-and-likelihood-assessment",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.bcm-institute.org/hubfs/BCMI%20Logo.png"
    },
    "name" : "BCMI Pte Ltd"
  }
}
```